NZ Herald
  • Home
  • Latest news
  • Herald NOW
  • Video
  • New Zealand
  • Sport
  • World
  • Business
  • Entertainment
  • Podcasts
  • Quizzes
  • Opinion
  • Lifestyle
  • Travel
  • Viva
  • Weather

Subscriptions

  • Herald Premium
  • Viva Premium
  • The Listener
  • BusinessDesk

Sections

  • Latest news
  • New Zealand
    • All New Zealand
    • Crime
    • Politics
    • Education
    • Open Justice
    • Scam Update
  • Herald NOW
  • On The Up
  • World
    • All World
    • Australia
    • Asia
    • UK
    • United States
    • Middle East
    • Europe
    • Pacific
  • Business
    • All Business
    • MarketsSharesCurrencyCommoditiesStock TakesCrypto
    • Markets with Madison
    • Media Insider
    • Business analysis
    • Personal financeKiwiSaverInterest ratesTaxInvestment
    • EconomyInflationGDPOfficial cash rateEmployment
    • Small business
    • Business reportsMood of the BoardroomProject AucklandSustainable business and financeCapital markets reportAgribusiness reportInfrastructure reportDynamic business
    • Deloitte Top 200 Awards
    • CompaniesAged CareAgribusinessAirlinesBanking and financeConstructionEnergyFreight and logisticsHealthcareManufacturingMedia and MarketingRetailTelecommunicationsTourism
  • Opinion
    • All Opinion
    • Analysis
    • Editorials
    • Business analysis
    • Premium opinion
    • Letters to the editor
  • Politics
  • Sport
    • All Sport
    • OlympicsParalympics
    • RugbySuper RugbyNPCAll BlacksBlack FernsRugby sevensSchool rugby
    • CricketBlack CapsWhite Ferns
    • Racing
    • NetballSilver Ferns
    • LeagueWarriorsNRL
    • FootballWellington PhoenixAuckland FCAll WhitesFootball FernsEnglish Premier League
    • GolfNZ Open
    • MotorsportFormula 1
    • Boxing
    • UFC
    • BasketballNBABreakersTall BlacksTall Ferns
    • Tennis
    • Cycling
    • Athletics
    • SailingAmerica's CupSailGP
    • Rowing
  • Lifestyle
    • All Lifestyle
    • Viva - Food, fashion & beauty
    • Society Insider
    • Royals
    • Sex & relationships
    • Food & drinkRecipesRecipe collectionsRestaurant reviewsRestaurant bookings
    • Health & wellbeing
    • Fashion & beauty
    • Pets & animals
    • The Selection - Shop the trendsShop fashionShop beautyShop entertainmentShop giftsShop home & living
    • Milford's Investing Place
  • Entertainment
    • All Entertainment
    • TV
    • MoviesMovie reviews
    • MusicMusic reviews
    • BooksBook reviews
    • Culture
    • ReviewsBook reviewsMovie reviewsMusic reviewsRestaurant reviews
  • Travel
    • All Travel
    • News
    • New ZealandNorthlandAucklandWellingtonCanterburyOtago / QueenstownNelson-TasmanBest NZ beaches
    • International travelAustraliaPacific IslandsEuropeUKUSAAfricaAsia
    • Rail holidays
    • Cruise holidays
    • Ski holidays
    • Luxury travel
    • Adventure travel
  • Kāhu Māori news
  • Environment
    • All Environment
    • Our Green Future
  • Talanoa Pacific news
  • Property
    • All Property
    • Property Insider
    • Interest rates tracker
    • Residential property listings
    • Commercial property listings
  • Health
  • Technology
    • All Technology
    • AI
    • Social media
  • Rural
    • All Rural
    • Dairy farming
    • Sheep & beef farming
    • Horticulture
    • Animal health
    • Rural business
    • Rural life
    • Rural technology
    • Opinion
    • Audio & podcasts
  • Weather forecasts
    • All Weather forecasts
    • Kaitaia
    • Whangārei
    • Dargaville
    • Auckland
    • Thames
    • Tauranga
    • Hamilton
    • Whakatāne
    • Rotorua
    • Tokoroa
    • Te Kuiti
    • Taumaranui
    • Taupō
    • Gisborne
    • New Plymouth
    • Napier
    • Hastings
    • Dannevirke
    • Whanganui
    • Palmerston North
    • Levin
    • Paraparaumu
    • Masterton
    • Wellington
    • Motueka
    • Nelson
    • Blenheim
    • Westport
    • Reefton
    • Kaikōura
    • Greymouth
    • Hokitika
    • Christchurch
    • Ashburton
    • Timaru
    • Wānaka
    • Oamaru
    • Queenstown
    • Dunedin
    • Gore
    • Invercargill
  • Meet the journalists
  • Promotions & competitions
  • OneRoof property listings
  • Driven car news

Puzzles & Quizzes

  • Puzzles
    • All Puzzles
    • Sudoku
    • Code Cracker
    • Crosswords
    • Cryptic crossword
    • Wordsearch
  • Quizzes
    • All Quizzes
    • Morning quiz
    • Afternoon quiz
    • Sports quiz

Regions

  • Northland
    • All Northland
    • Far North
    • Kaitaia
    • Kerikeri
    • Kaikohe
    • Bay of Islands
    • Whangarei
    • Dargaville
    • Kaipara
    • Mangawhai
  • Auckland
  • Waikato
    • All Waikato
    • Hamilton
    • Coromandel & Hauraki
    • Matamata & Piako
    • Cambridge
    • Te Awamutu
    • Tokoroa & South Waikato
    • Taupō & Tūrangi
  • Bay of Plenty
    • All Bay of Plenty
    • Katikati
    • Tauranga
    • Mount Maunganui
    • Pāpāmoa
    • Te Puke
    • Whakatāne
  • Rotorua
  • Hawke's Bay
    • All Hawke's Bay
    • Napier
    • Hastings
    • Havelock North
    • Central Hawke's Bay
    • Wairoa
  • Taranaki
    • All Taranaki
    • Stratford
    • New Plymouth
    • Hāwera
  • Manawatū - Whanganui
    • All Manawatū - Whanganui
    • Whanganui
    • Palmerston North
    • Manawatū
    • Tararua
    • Horowhenua
  • Wellington
    • All Wellington
    • Kapiti
    • Wairarapa
    • Upper Hutt
    • Lower Hutt
  • Nelson & Tasman
    • All Nelson & Tasman
    • Motueka
    • Nelson
    • Tasman
  • Marlborough
  • West Coast
  • Canterbury
    • All Canterbury
    • Kaikōura
    • Christchurch
    • Ashburton
    • Timaru
  • Otago
    • All Otago
    • Oamaru
    • Dunedin
    • Balclutha
    • Alexandra
    • Queenstown
    • Wanaka
  • Southland
    • All Southland
    • Invercargill
    • Gore
    • Stewart Island
  • Gisborne

Media

  • Video
    • All Video
    • NZ news video
    • Herald NOW
    • Business news video
    • Politics news video
    • Sport video
    • World news video
    • Lifestyle video
    • Entertainment video
    • Travel video
    • Markets with Madison
    • Kea Kids news
  • Podcasts
    • All Podcasts
    • The Front Page
    • On the Tiles
    • Ask me Anything
    • The Little Things
  • Cartoons
  • Photo galleries
  • Today's Paper - E-editions
  • Photo sales
  • Classifieds

NZME Network

  • Advertise with NZME
  • OneRoof
  • Driven Car Guide
  • BusinessDesk
  • Newstalk ZB
  • Sunlive
  • ZM
  • The Hits
  • Coast
  • Radio Hauraki
  • The Alternative Commentary Collective
  • Gold
  • Flava
  • iHeart Radio
  • Hokonui
  • Radio Wanaka
  • iHeartCountry New Zealand
  • Restaurant Hub
  • NZME Events

SubscribeSign In
Advertisement
Advertise with NZME.
Home / Business

Ross Boswell: Password policy has passed its expiry date

By Ross Boswell
NZ Herald·
12 Jun, 2019 05:00 PM5 mins to read

Subscribe to listen

Access to Herald Premium articles require a Premium subscription. Subscribe now to listen.
Already a subscriber?  Sign in here

Listening to articles is free for open-access content—explore other articles or learn more about text-to-speech.
‌
Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Official advice in the UK and the US on good practice with passwords has changed in recent times. Photo / File

Official advice in the UK and the US on good practice with passwords has changed in recent times. Photo / File

Opinion

COMMENT

Do you grind your teeth while dealing with your employer's IT system and its password rules? Do you have to change your password every six or 12 weeks, and must the new password have some combination of upper and lower case letters, digits and special characters? Have you found it impossible to remember the new password, and written it down on a scrap of paper or Post-It note?

Have you wondered why this user-hostile regime is forced upon you?

If your enterprise is based in New Zealand, and especially if it is a government department, then the responsibility for your frustration belongs with the Government Communications Security Bureau (GCSB), and specifically, with the NZ Security Information Manual (NZISM) which it issues.

Highly complex memorised secrets introduce a new potential vulnerability: they are less likely to be memorable, and it is more likely that they will be written down.

Advertisement
Advertise with NZME.

The current version, published in December 2018, directs that agencies (other than those
classified as Confidential, Secret and Top Secret for which more stringent rules are required): "Should implement a password policy enforcing either a minimum password length of 16 characters with no complexity requirement; or a minimum password length of 10 characters."

In both cases passwords should consist of at least three of the following character sets: Lowercase characters (a-z); uppercase characters (A-Z); digits (0-9); and punctuation and special characters.

Additionally, users should: Ensure passwords are changed at least every 90 days; prevent system users from changing their password more than once a day; check passwords for compliance with their password selection policy where the system cannot be configured to enforce complexity requirements; and force the system user to change an expired password on initial logon or if the password is reset.

Although the NZISM has been regularly updated, these requirements are identical to those in the oldest version available on the GCSB website, which is dated November 2015.

Advertisement
Advertise with NZME.

It surprises many users to learn that any reasonable computer system does not store their
password. What it stores is an encrypt of the password: the result of a complex mathematical algorithm that turns the password into a long binary number. The encryption is a one-way process, and it is not possible to get from that number back to the original password. Instead, when you key in your password as you log in, your input is put through the same encryption process and the result is compared with the stored value. If they match, you are granted access; if not, access is denied.

This is the reason your IT department cannot (or certainly should not) be able to tell you what your lost password is; since it cannot readily get from the stored value to the original password, the response is to require you to set a new password.

Discover more

Opinion

Wiremu Doherty: Only bilingual training will truly speak to Māori

02 Jun 05:00 PM
Opinion

Robert MacCulloch: Quality of life neglected in Wellbeing Budget

09 Jun 05:00 PM
Opinion

Louise Aubin: Give hope to those without - by being a friend

10 Jun 05:00 PM
Opinion

Chris Baker: Let's talk about coal and climate change

11 Jun 05:00 PM

The only way to recover a lost password is by trial-and-error: by guessing what it might be, encrypting that guess, and comparing that encrypt with the stored value. Guessing an unknown password is feasible in practice only if the cracker has access to the stored encrypt and can use an automated procedure on another computer to make many thousands of guesses. It follows that (s)he must already have cracked the system on which your password encrypt is stored, and in that case the horse has already bolted.

What about the requirement for passwords to expire? That originated because early computers were so slow that given a password encrypt, it would take weeks of trial-and-error to guess the password. A back-of-envelope calculation suggested that a reasonable password could survive at least three months of such attempts, so passwords were allowed a lifetime of three months.

The world has moved on. The NZISM asserts that "a simple eight-letter password can today be bruteforced in minutes by software freely available on the internet". So the key to computer security in 2019 is not that you should routinely change your password, but that your IT department should make sure that crackers cannot get hold of its encrypt.

Given these basic facts, official advice has been changing. The United Kingdom Government Communications Headquarters (GCHQ) published Password Guidance: Simplifying Your Approach in 2015, advising that "enforcing the requirement for complex character sets is not recommended" and "regular password changing harms rather than improves security" (that means you, and your scrap of paper or Post-It note).

The US National Institute of Standards and Technology (NIST) issues IT security policies for US Government organisations. The current version of the NIST Digital Identity Guidelines, published in June 2017, has also abandoned both password complexity and password expiry: Verifiers should not impose other composition rules (e.g. requiring mixtures of different character types or prohibiting consecutively repeated characters) for memorised secrets; Verifiers should not require memorised secrets to be changed arbitrarily (e.g.
periodically); However, verifiers shall force a change if there is evidence of compromise of the authenticator.

The NIST guidelines very sensibly note that: "Highly complex memorised secrets introduce a new potential vulnerability: they are less likely to be memorable, and it is more likely that they will be written down."

Advertisement
Advertise with NZME.

It is clear from their moderate and practical proposals that the GCHQ and NIST have heeded expert advice, research both published and unpublished, and feedback from users who are required to live with their policies.

Why then, almost four years after the publication of the GCHQ recommendations and two years after the finalisation of the NIST guidelines, is New Zealand's GCSB unwilling to make similar changes to reduce the frustration caused by its policies?

The disturbing conclusion, given its role as the government's eavesdropping agency, is the GCSB is apparently not listening.

• Ross Boswell is a pathologist and physician in the public hospital system

Save

    Share this article

    Reminder, this is a Premium article and requires a subscription to read.

Latest from Business

Premium
Airlines

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM
Premium
Business

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Shares

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM

Audi offers a sporty spin on city driving with the A3 Sportback and S3 Sportback

sponsored
Advertisement
Advertise with NZME.

Latest from Business

Premium
Pilot group to honour Erebus legacy with safety award

Pilot group to honour Erebus legacy with safety award

17 Jun 07:00 AM

The industry faces challenges but hopes to bring newcomers and veterans together.

Premium
The NZ boardrooms where women buck gender pay gap trend

The NZ boardrooms where women buck gender pay gap trend

17 Jun 06:00 AM
Premium
Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

Market close: NZX 50 down 0.4% as Israel-Iran conflict intensifies

17 Jun 05:48 AM
Median house prices down again, sales taking longer: monthly report

Median house prices down again, sales taking longer: monthly report

17 Jun 05:32 AM
Gold demand soars amid global turmoil
sponsored

Gold demand soars amid global turmoil

NZ Herald
  • About NZ Herald
  • Meet the journalists
  • Newsletters
  • Classifieds
  • Help & support
  • Contact us
  • House rules
  • Privacy Policy
  • Terms of use
  • Competition terms & conditions
  • Our use of AI
Subscriber Services
  • NZ Herald e-editions
  • Daily puzzles & quizzes
  • Manage your digital subscription
  • Manage your print subscription
  • Subscribe to the NZ Herald newspaper
  • Subscribe to Herald Premium
  • Gift a subscription
  • Subscriber FAQs
  • Subscription terms & conditions
  • Promotions and subscriber benefits
NZME Network
  • The New Zealand Herald
  • The Northland Age
  • The Northern Advocate
  • Waikato Herald
  • Bay of Plenty Times
  • Rotorua Daily Post
  • Hawke's Bay Today
  • Whanganui Chronicle
  • Viva
  • NZ Listener
  • Newstalk ZB
  • BusinessDesk
  • OneRoof
  • Driven Car Guide
  • iHeart Radio
  • Restaurant Hub
NZME
  • About NZME
  • NZME careers
  • Advertise with NZME
  • Digital self-service advertising
  • Book your classified ad
  • Photo sales
  • NZME Events
  • © Copyright 2025 NZME Publishing Limited
TOP